White Paper Overview

The Contact Initiative: A National Framework for Verified Identity, Version 5

The full white paper lays out a federated, four-layer identity architecture and applies it to K–12 School Contact, plus the companion College Contact and University Contact proposals. Below is a section-by-section map of what it covers.

The Core Idea vs. Implementation

Version 5’s most important change: it separates the core idea — that verified identity and scoped authorization should be shared education infrastructure — from any single implementation detail. The paper replaces an earlier single, centrally issued national identifier with a federated model in which local systems keep the underlying records and a national layer holds only short-lived, revocable attestations.

What’s Inside

  • The Problem — fragmented identity, shadow IT, and unverifiable contact across roughly 13,000 K–12 districts and thousands of colleges and universities.
  • The Four-Layer Model — identity anchor, federation/attestation layer, alias layer, and relationship/authorization layer.
  • Communication Architecture — role-based aliases and query-response verification instead of a public, browsable directory.
  • Machine-Intelligence Authorization Layer — scoped, human-approved, auditable grants for MI assistants.
  • Cybersecurity, Legal Compliance & Privacy, and Accessibility — the guardrails the architecture is built around, including FERPA, COPPA, IDEA, and WCAG 2.2 AA.
  • Governance, Risks, and a Phased Pilot Roadmap — including an appendix of open legal questions still requiring counsel and regulator review.

Where this paper describes a numbering pattern, a domain name, or a specific technical mechanism, it is describing one illustrative way to satisfy the underlying principle — not the only way, and not a claim of endorsement by any government body, standards organization, or accrediting entity.

Explore the ideas in more depth on the blog, organized by topic: identity architecture, communication and phishing resistance, MI authorization, cybersecurity, privacy and legal compliance, accessibility, costs and governance, and risk mitigation.